unified
UC-ASSET-10 — Assess and track changes and exceptions for risk impact
Manage changes and exceptions to the environment and to security requirements through a process that assesses risk impact before approval. Record each change or exception with its assessment, approver, owner, and expiry or review date, and track open items to closure.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-ASSET-10
- title
- Assess and track changes and exceptions for risk impact
- statement
- Manage changes and exceptions to the environment and to security requirements through a process that assesses risk impact before approval. Record each change or exception with its assessment, approver, owner, and expiry or review date, and track open items to closure.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- ID.RA-07
- coverage
- full
- relationship
- equal
- guidance
Source
No record-specific source URL is provided.
Connections
- Vulnerability & Patch Management Cycle operates UC-ASSET-10 — Assess and track changes and exceptions for risk impact
- Policy Exception & Risk Acceptance oversees UC-ASSET-10 — Assess and track changes and exceptions for risk impact
- UC-ASSET-10 — Assess and track changes and exceptions for risk impact maps_to ID.RA-07 — Risk Assessment: Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
- framework
- nist-csf-2
- control_id
- ID.RA-07
- coverage
- full
- relationship
- equal
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-10 — Assess and track changes and exceptions for risk impact mitigates Failed M&A, integration or divestiture
- strength
- related
- rationale
- UC-ASSET-10 — Assess and track changes and exceptions for risk impact mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Assessing and expiring exceptions to security requirements reduces lingering security gaps that attackers exploit, shrinking attack surface.